CWE-79
47,413 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
CVEs (47,413)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Jenkins vboxwrapper Plugin 1.3 and earlier does not escape the name and description of VBox node parameters on views displaying parameters, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by at...Show more |
Jenkins Selection tasks Plugin 1.0 and earlier does not escape the name and description of Script Selection task variable parameters on views displaying parameters, resulting in a stored cross-site scripting (XSS) vulner...Show more |
Jenkins Promoted Builds (Simple) Plugin 1.9 and earlier does not escape the name and description of Promotion Level parameters on views displaying parameters, resulting in a stored cross-site scripting (XSS) vulnerabilit...Show more |
1Jenkins 1Multiselect Parameter Jun 17, 2026 May 17, 2022 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 Jenkins Multiselect parameter Plugin 1.3 and earlier does not escape the name and description of Multiselect parameters on views displaying parameters, resulting in a stored cross-site scripting (XSS) vulnerability explo...Show more |
Jenkins JDK Parameter Plugin 1.0 and earlier does not escape the name and description of JDK parameters on views displaying parameters, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attack...Show more |
1Jenkins 1Global Variable String Parameter Jun 17, 2026 May 17, 2022 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 Jenkins Global Variable String Parameter Plugin 1.2 and earlier does not escape the name and description of Global Variable String parameters on views displaying parameters, resulting in a stored cross-site scripting (XS...Show more |
1Jenkins 1Autocomplete Parameter Jun 17, 2026 May 17, 2022 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 Jenkins Autocomplete Parameter Plugin 1.1 and earlier does not escape the name of Dropdown Autocomplete and Auto Complete String parameters on views displaying parameters, resulting in a stored cross-site scripting (XSS)...Show more |
Jenkins Application Detector Plugin 1.0.8 and earlier does not escape the name of Chois Application Version parameters on views displaying parameters, resulting in a stored cross-site scripting (XSS) vulnerability exploi...Show more |
Jenkins Rundeck Plugin 3.6.10 and earlier does not restrict URL schemes in Rundeck webhook submissions, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to submit crafted Runde...Show more |
The file preview functionality in Jirafeau < 4.4.0, which is enabled by default, could be exploited for cross site scripting. An attacker could upload image/svg+xml files containing JavaScript. When someone visits the Fi...Show more |
Stored cross-site scripting (XSS) in admin/usermanager.php over IPPlan v4.92b allows remote attackers to inject arbitrary web script or HTML via the userid parameter. |
1Arubanetworks 1Clearpass Policy Manager Jun 17, 2026 May 16, 2022 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 A remote reflected cross site scripting (xss) vulnerability was discovered in Aruba ClearPass Policy Manager version(s): 6.10.4 and below, 6.9.9 and below, 6.8.9-HF2 and below, 6.7.x and below. Aruba has released updates...Show more |
xArrow SCADA versions 7.2 and prior permits unvalidated registry keys to be run with application-level privileges. |
xArrow SCADA versions 7.2 and prior is vulnerable to cross-site scripting due to parameter ‘edate’ of the resource xhisalarm.htm, which may allow an unauthorized attacker to execute arbitrary code. |
xArrow SCADA versions 7.2 and prior is vulnerable to cross-site scripting due to parameter ‘bdate’ of the resource xhisvalue.htm, which may allow an unauthorized attacker to execute arbitrary code. |
1Weintek 16Cmt Ctrl01 Firmware Cmt Fhd FirmwareCmt G01 Firmware+13 moreJun 17, 2026 May 16, 2022 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The Weintek cMT product line is vulnerable to a cross-site scripting vulnerability, which could allow an unauthenticated remote attacker to inject malicious JavaScript code. |
Gnuboard 5.55 and 5.56 is vulnerable to Cross Site Scripting (XSS) via bbs/member_confirm.php. |
1Bootstrap Table 1Bootstrap Table Jun 17, 2026 May 16, 2022 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 Bootstrap Tables XSS vulnerability with Table Export plug-in when exportOptions: htmlContent is true in GitHub repository wenzhixin/bootstrap-table prior to 1.20.2. Disclosing session cookies, disclosing secure session d...Show more |
The Clipr WordPress plugin through 1.2.3 does not sanitise and escape its API Key settings before outputting it in an attribute, leading to a Stored Cross-Site Scripting issue even when the unfiltered_html capability is...Show more |
1Uleak Security Dashboard Project 1Uleak Security Dashboard Jun 17, 2026 May 16, 2022 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 The ULeak Security & Monitoring WordPress plugin through 1.2.3 does not have authorisation and CSRF checks when updating its settings, and is also lacking sanitisation as well as escaping in some of them, which could all...Show more |